The Centers for Medicare & Medicaid Services (CMS) has announced that starting October 15, 2026, it will “require probationary prior authorization for certain DMEPOS items billed by newly enrolled suppliers and suppliers undergoing certain changes of ownership.”
The policy is one of several recent developments focusing greater attention on durable medical equipment, prosthetics, orthotics, and supplies (DMEPOS) suppliers before claims are paid. Beginning this year, CMS also increased the frequency of DMEPOS supplier reaccreditation from once every three years to annually and established new requirements affecting certain changes in majority ownership. In February 2026, CMS imposed a six-month nationwide moratorium on initial enrollment and changes in majority ownership for seven categories of DMEPOS suppliers, saying the pause would give it time to explore additional safeguards. The moratorium expired August 27 after the agency declined to extend it.
In addition, the Department of Health and Human Services Office of Inspector General (HHS-OIG) has published two reports (here and here) examining vulnerabilities in DMEPOS program integrity. The identified issues are associated with supplier enrollment and ownership, physician orders, beneficiary identification information, and oversight of suppliers billing Medicare Advantage (MA).
From “Pay and Chase” Toward Prevention
We are seeing an increasingly “front-end” approach to DMEPOS program integrity as CMS shifts its focus from recovering questionable payments after the fact to preventing them in the first place.
In March 2025, the agency launched its Fraud Defense Operations Center, also known as the Medicare War Room, to use data analytics to identify suspicious billing and suspend payments. CMS told OIG that during the center’s first year (March 31, 2025, through March 31, 2026), it suspended more than $2.1 billion in potentially fraudulent payments, including more than $1.9 billion associated with suspect DMEPOS billing. CMS said it subsequently revoked the Traditional Medicare billing privileges of nearly 100 of the suppliers whose payments were suspended and added 21 of them to the Medicare Advantage Preclusion List. From January through June 2026, the center suspended more than $371 million, including more than $226 million tied to suspect durable medical equipment billing.
OIG Identifies Gaps
In its August white paper, OIG examined vulnerabilities involving three elements necessary to carry out DMEPOS fraud: an enrolled supplier, a physician order, and a Medicare enrollee identification number. Its September issue brief focused on Medicare Advantage, examining gaps in the screening of DMEPOS suppliers and recommending additional steps for CMS and Medicare Advantage organizations. CMS concurred with or agreed to consider all the issue brief’s recommendations.
Who Controls the Supplier
Recent fraud cases have sharpened CMS’s focus on who actually controls DMEPOS suppliers, not just who is listed on their enrollment records. In Operation Gold Rush, federal prosecutors alleged that a transnational criminal organization bought dozens of DME companies that were already able to bill Medicare, installed nominee owners, and created fictitious corporate records to conceal who actually controlled them. The organization then submitted more than $10.6 billion in fraudulent Medicare claims. CMS and OIG blocked most of those payments, but Medicare still paid approximately $41 million, and Medicare supplemental insurers paid an estimated $900 million.
CMS has extended its so-called 36-month rule to DMEPOS suppliers. When a supplier undergoes certain changes in majority ownership within 36 months of its initial enrollment or most recent change in majority ownership, its Medicare billing privileges generally do not transfer to the new owner. Subject to specified exceptions, the new owner must enroll as a new DMEPOS supplier and undergo a new survey and accreditation.
The same rule tightened accreditation. Whereas CMS had previously accredited DMEPOS suppliers for three-year terms, it implemented an annual reaccreditation requirement on January 1, 2026.[1] The agency also eliminated a provision that had allowed an existing supplier’s new location to be accredited for three months without a site visit. Under current guidelines, new locations must be surveyed before accreditation.
OIG’s scrutiny of enrollment safeguards is continuing. Two active audits are examining whether Medicare enrollment contractors appropriately screened DMEPOS suppliers, with the series expected to be completed in fiscal year 2027. A separate ongoing evaluation is revisiting CMS’s use of DME surety bonds, including whether changes could make them more effective at deterring fraud and recovering overpayments.
Medicare Advantage Exposes Gaps
OIG’s September issue brief identified a related vulnerability in Medicare Advantage: DMEPOS suppliers can bill MA plans without enrolling in Traditional Medicare and undergoing its supplier screening process. Medicare enrollment is distinct from participation, which determines whether a supplier has agreed to accept assignment on all Medicare claims, and from network status, which reflects a supplier’s contractual relationship with an MA organization. Complicating matters, “nonparticipating” is sometimes used to describe suppliers without an MA plan contract, and responses to CMS’s request for information (RFI) on its Comprehensive Regulations to Uncover Suspicious Healthcare (CRUSH) initiative, discussed below, used the term both ways.
Among 21,029 DMEPOS suppliers that billed the six MA organizations OIG reviewed, 13,049 billed exclusively out of network and 1,342 were not enrolled in Medicare. OIG identified 1,151 suppliers that were both out of network and not Medicare-enrolled, the group subject to the least screening. For orthotics, MA organizations reported paying these suppliers an average of $1,399 per enrollee, nearly seven times the $210 average for other suppliers. The six organizations are not necessarily representative of all MA plans, although together they accounted for approximately two-thirds of MA enrollment.
MA organizations and investigators also told OIG that recent fraud schemes have involved suppliers outside plan networks or Medicare enrollment. OIG investigators said some bad actors have avoided oversight by intentionally remaining out of network and unenrolled.
Health plans have also called for stronger front-end controls. In its response to the CRUSH RFI, the Blue Cross Blue Shield Association (BCBSA) supported requiring nonparticipating (that is, out-of-network) DMEPOS suppliers to meet Traditional Medicare enrollment and accreditation standards before billing MA plans. The group also recommended that plans have improved access to supplier accreditation, enforcement, and other risk information, and tools to identify unusual billing earlier.
Connecting the Dots
Collecting information about program participants can be an important step toward curtailing fraudulent activity, but fraud prevention ultimately requires the ability to “connect the dots.” The value of information about enrollment, ownership, ordering, billing, and payment lies in being able to identify inconsistencies and emerging patterns before questionable claims are paid.
OIG has repeatedly pointed to this issue in Medicare Advantage. In 2020, it reported that ordering-provider identifiers were missing from about 60% of 2018 MA encounter records for DMEPOS, laboratory, imaging, and home health services, even though nearly all MA organizations it surveyed had systems capable of receiving and storing the information. In a follow-up brief, OIG noted that one in five MA organizations collecting ordering-provider identifiers did not use them for program-integrity oversight.
In its August 2026 white paper, OIG called for CMS to require MA organizations to submit ordering-provider National Provider Identifiers (NPIs) on DMEPOS encounter records. It also recommended the use of data analytics and artificial intelligence (AI) to identify suspicious billing and potentially fraudulent documentation. In addition, OIG called for closer coordination between CMS and Medigap insurers and other secondary payers, which might otherwise continue paying a supplier’s claims even after CMS suspends its own payments.
CRUSH
Several of the issues highlighted in OIG’s most recent reports were already under consideration at CMS. In the CRUSH RFI, issued in February, the agency asked whether DMEPOS suppliers billing Medicare Advantage should be required to enroll in Traditional Medicare and whether changes to the Preclusion List could strengthen oversight. The agency also sought input on payment suspensions, stronger identity and ownership verification, and changes to the $50,000 DMEPOS surety-bond requirement. Other questions addressed whether restrictions on unsolicited DMEPOS telephone contacts should extend to email, text messages, and social media, as well as to third parties acting on suppliers’ behalf. CMS also asked whether the claims-filing period should be shortened for services at heightened risk for fraud, including DMEPOS.
In its response to the CRUSH RFI, the American Association for Homecare (AAHomecare), which represents DMEPOS suppliers and manufacturers, supported several stronger safeguards. It recommended stronger identity verification for new suppliers, better-qualified site inspectors, and additional front-end controls, such as monitoring new suppliers’ electronic funds transfers and expanding prior authorization for high-risk items. However, AAHomecare argued against across-the-board requirements that would impose the same scrutiny on suppliers with proven compliance histories. The organization maintains that Medicare participation status, which it describes as primarily a matter of payment terms, “has no influence on fraud risk and should not be used as a fraud control mechanism.”
The questions facing CMS extend beyond whether additional safeguards are warranted. They include how effectively the agency can direct additional scrutiny toward higher-risk entities and activities without unnecessarily increasing administrative burdens for legitimate suppliers.
Looking Ahead
Several pieces of the emerging DMEPOS program-integrity framework remain unsettled. As CMS prepares to implement its new probationary prior authorization process, OIG is continuing work on supplier enrollment screening, surety bonds, and the Medicare Advantage Preclusion List. Questions remain about whether and how Medicare enrollment requirements for DMEPOS suppliers billing Medicare Advantage might change, whether CMS will require additional ordering-provider data, and how the agency could address third-party marketing and digital solicitation.
A CRUSH proposed rule, which CMS sent to the Office of Management and Budget for review in August, could provide important information about CMS’s priorities.
For established healthcare organizations, recent changes in program integrity do not necessarily mean that familiar compliance obligations have changed. Rather, they suggest that CMS and OIG will place increased emphasis on the circumstances surrounding a claim before it is paid.
Applied Policy will continue to monitor changes in federal DMEPOS program-integrity efforts and priorities, including any CRUSH proposed rule, the rollout of probationary prior authorization, and OIG’s ongoing work on enrollment screening, surety bonds, and the Preclusion List.
[1] Suppliers accredited prior to January 1, 2026, move to the annual cycle only when their current three-year term expires.
